Uniqcli

InsightsCompliance

Section 889 Surveillance BOM: A Component-Level Checklist

Section 889 compliance screening cannot stop at the logo on a camera. A defensible review follows the system through cameras, recorders, radios, management software, cloud services, and the entities that provide them—then preserves the manufacturer and supplier evidence behind the decision.

By Uniqcli Team · · 11 min read

Macro photograph of an electronic circuit board with integrated circuits and soldered components.
Macro photograph of an electronic circuit board with integrated circuits and soldered components.

Key takeaways

  • Section 889 Part A addresses federal procurement of covered telecommunications equipment or services; Part B addresses contracting with an entity that uses covered equipment or services. They are related but different representations.
  • Covered sources named in the statute and FAR include Huawei and ZTE, plus Hytera, Hikvision, and Dahua when their telecommunications or video-surveillance equipment is used for public-safety, facility-security, critical-infrastructure-security, or other national-security purposes, as well as specified affiliates or subsidiaries.
  • A “reasonable inquiry” is not defined as a mandatory internal or third-party audit. It still needs a documented scope, reliable questions, and an accountable signer.
  • There is no universal federal “NDAA camera certificate.” Supplier attestations are evidence inputs, not a substitute for reading the solicitation and applicable FAR clauses.
  • Do not mark every semiconductor from a named company as automatically covered without analysis. Screen the producer, function, service, role in the system, and whether the item is a substantial or essential component or critical technology.
  • Verify clause language in the actual solicitation. The FAR is undergoing updates and agencies may use class deviations, so a memorized clause number is not enough.
On this page
The answer first: what should procurement review?Section 889 in plain procurement languageKnow what “covered” means before checking boxesThe component-level surveillance BOMCameras and sensorsRecorders, gateways, and encodersNetwork and radio equipmentSoftware, applications, and cloud servicesAccessories that change identity or communicationsA working evidence tableA step-by-step Section 889 reviewStep 1: copy the applicable requirement verbatimStep 2: establish the product boundaryStep 3: resolve manufacturer identityStep 4: screen named producers, subsidiaries, and affiliatesStep 5: evaluate function and materialityStep 6: conduct and document the Part B reasonable inquiryStep 7: reconcile supplier evidenceStep 8: control substitutionsStep 9: verify at receiving and commissioningSupplier questions that produce usable answersCommon failure modesWhat to keep in the fileFrequently asked questions

Compliance

The answer first: what should procurement review?

Build two views of the purchase.

The first is a system bill of materials: every camera, recorder, network device, radio, appliance, software platform, mobile app, cloud service, and material subcomponent identified by the manufacturer or integrator. The second is an entity and use map: the offeror, subsidiaries, service providers, manufacturers, distributors, and the places where covered equipment or services may be used.

Then test each row against the solicitation's Section 889 representation and prohibition language. Record the evidence, who supplied it, when it was checked, and any unresolved issue. A clean product list without the Part B entity inquiry is incomplete. A broad company representation without checking the proposed surveillance system is also incomplete.

This checklist supports supplier diligence; it does not determine legal compliance for every fact pattern. Contracting counsel or the contracting officer should resolve ambiguous coverage and disclosure questions.

Section 889 in plain procurement language

Section 889 of the fiscal year 2019 National Defense Authorization Act created restrictions involving certain telecommunications and video-surveillance equipment and services.

Part A has applied since August 13, 2019. In practical terms, an executive agency may not procure or obtain, or extend or renew a contract to procure or obtain, equipment, a system, or a service that uses covered telecommunications equipment or services as a substantial or essential component or as critical technology.

Part B has applied since August 13, 2020. It restricts an executive agency from contracting with an entity that uses covered telecommunications equipment or services, subject to the governing rules and exceptions. The entity's use can matter even when the covered equipment is not part of the item being sold to the government.

The official acquisition.gov Section 889 page is the best starting point for current policy resources, FAQs, and waiver material. The operative decision must also consider the solicitation, current FAR text, agency deviations, and any agency-specific instruction.

Know what “covered” means before checking boxes

The FAR definition names:

  • telecommunications equipment produced by Huawei Technologies Company or ZTE Corporation, or their subsidiaries and affiliates;
  • for public safety, security of government facilities, physical security surveillance of critical infrastructure, and other national-security purposes, video-surveillance and telecommunications equipment produced by Hytera Communications Corporation, Hangzhou Hikvision Digital Technology Company, or Dahua Technology Company, or their subsidiaries and affiliates;
  • telecommunications or video-surveillance services provided by those entities or using such equipment; and
  • other entities that the Secretary of Defense, in consultation with the Director of National Intelligence or the Director of the FBI, reasonably believes are connected to the government of a covered foreign country, as provided by the rule.

The definition and the “substantial or essential component” and “critical technology” tests matter. Procurement teams should resist two shortcuts: “the finished product has a different logo, so it is fine” and “one chip with a familiar name makes the entire system prohibited.” Either conclusion can skip the necessary facts.

The component-level surveillance BOM

Use a separate row for each orderable item and each material embedded or service component the manufacturer identifies. At minimum, capture the following.

Cameras and sensors

  • manufacturer legal name and brand;
  • exact model and hardware revision;
  • original equipment manufacturer if the label is private-brand;
  • image-signal processor or system-on-chip manufacturer and part number when disclosed;
  • radio or cellular module manufacturer;
  • firmware version and update source;
  • country of origin and substantial-transformation statement when required;
  • ONVIF or other interoperability profile, if relevant to the design; and
  • signed Section 889 response tied to the exact model family.

Do not treat country of origin as a substitute for producer identity. A device assembled in one country can contain components and software from many sources. The reverse is also true: origin by itself does not establish that an item is covered.

Recorders, gateways, and encoders

Capture NVRs, DVRs, encoders, video gateways, analytics appliances, and any server image supplied with the solution. Identify motherboard or appliance OEM, capture-card manufacturer, storage controller, network interfaces, management software, and firmware.

These devices are easy to overlook when attention stays on the camera. They may be central to the system's operation and therefore deserve at least the same evidence quality.

Network and radio equipment

List switches, routers, cellular gateways, wireless bridges, antennas with active electronics, modems, and out-of-band management devices. If an integrator says this equipment is “customer furnished,” assign ownership for screening instead of deleting it from the system view.

Software, applications, and cloud services

Record the video-management system, mobile application, analytics engine, device-discovery tool, remote-support platform, update service, and cloud storage or monitoring service. Include the legal entity providing each service and the hosting or subcontracting arrangement that the supplier discloses.

A camera can be acceptable as hardware while a proposed service creates a separate question. Conversely, a service name alone may obscure the device and network components used to deliver it.

Accessories that change identity or communications

Ordinary passive mounts and housings will rarely drive a Section 889 analysis, but active accessories can. Capture docking stations, communications modules, pan-tilt controllers, intercom modules, edge-compute boxes, and bundled wireless links. The useful boundary is not “expensive versus cheap”; it is whether the item supplies telecommunications, video-surveillance, or essential system functionality relevant to the rule.

A working evidence table

Camera model/revision

Producer/OEM: Legal entity. Function: Capture + network transmission. Covered-source screen: Named entities and disclosed affiliates checked. Evidence and date: OEM letter, product record, retrieval date. Part A disposition: Clear / escalate / replace. Open question/owner: Compliance lead.

NVR

Producer/OEM: Legal entity. Function: Recording and management. Covered-source screen: Producer and embedded platform reviewed. Evidence and date: Signed response + BOM. Part A disposition: Clear / escalate / replace. Open question/owner: Integrator.

Wireless bridge

Producer/OEM: Legal entity. Function: Telecommunications. Covered-source screen: Producer and service checked. Evidence and date: Datasheet + OEM response. Part A disposition: Clear / escalate / replace. Open question/owner: Network lead.

VMS cloud

Producer/OEM: Contracting entity and subcontractors. Function: Hosted management/service. Covered-source screen: Entity and service-use review. Evidence and date: Terms + supplier disclosure. Part A disposition: Clear / escalate / replace. Open question/owner: Contracting lead.

Integrator

Producer/OEM: Entity and affiliates. Function: Offeror and service provider. Covered-source screen: Part B reasonable inquiry. Evidence and date: Entity representation. Part A disposition: Represent / disclose / escalate. Open question/owner: Authorized signer.

“Clear” should mean the collected evidence supports the conclusion for the cited requirement—not that someone recognized the brand. “Escalate” is a valid interim answer. It is better than forcing uncertainty into a green cell.

A step-by-step Section 889 review

Step 1: copy the applicable requirement verbatim

Pull the Section 889 clauses, provisions, agency supplements, and proposal instructions from the current solicitation. Note the solicitation revision and amendment date. Do not rely only on an old compliance template: acquisition.gov warns users to follow current regulatory and agency material, and ongoing FAR changes can affect clause prescriptions and numbering.

Step 2: establish the product boundary

Draw the system from lens to user. Include power and communications paths, recorders, management consoles, remote maintenance, cloud services, and mobile access. Identify government-furnished and reused components. A diagram often exposes missing BOM rows faster than a spreadsheet.

Step 3: resolve manufacturer identity

For each active product, ask whether the selling brand manufactured it, commissioned a private-label design, or rebrands another OEM's model. Request the OEM identity in writing. Compare FCC records, manuals, firmware portals, MAC address prefixes, product photographs, and other official records only as supporting checks; none of those alone proves Section 889 status.

If a supplier refuses to identify the actual manufacturer, record the refusal and escalate. An unsupported “NDAA compliant” badge does not close the information gap.

Step 4: screen named producers, subsidiaries, and affiliates

Check the current official definitions and any agency-provided excluded-party or covered-entity resources. Legal names matter because brands, subsidiaries, and corporate ownership change. Record the search date and the exact entity reviewed.

Do not make a definitive affiliate finding from a search-engine result. Route uncertain ownership through counsel or the contracting authority and ask the supplier to make a signed representation.

Step 5: evaluate function and materiality

Describe what the questionable item does. Is it the camera, modem, radio, network gateway, or cloud service? Would the system perform its required mission without it? Does it handle communications or video surveillance? Is it critical technology as defined in the applicable rules?

This analysis is especially important for chipsets and embedded modules. The official Section 889 guide describes screening equipment, systems, and services and explains that the prohibition targets covered equipment used as a substantial or essential component or critical technology. It does not create a simple rule that every component from a named source produces the same result in every system. Ambiguous embedded-component questions deserve legal and contracting review, not an improvised bright line.

Step 6: conduct and document the Part B reasonable inquiry

The FAR definition says a reasonable inquiry is designed to uncover information in the entity's possession about the identity of the producer or provider of covered telecommunications equipment or services used by the entity. It need not include an internal or third-party audit.

Set a scope that matches the entity and representation. Suggested questions include:

  • Which legal entity will sign the offer and representation?
  • What subsidiaries, offices, networks, security systems, or managed services fall within the inquiry?
  • Who owns telecommunications and physical-security inventories?
  • Were vendor, accounts-payable, asset, and contract records searched?
  • Were responsible IT, facilities, security, legal, and procurement owners asked?
  • What date range and search terms were used?
  • What potential use was found, and has it been disclosed or resolved?
  • Who is authorized to sign the final representation?

Keep the inquiry memorandum. Do not attach sensitive internal network details to a public proposal unless required; maintain them in the controlled compliance file.

Step 7: reconcile supplier evidence

Evidence strength generally improves in this order:

  • undated marketing badge;
  • distributor statement covering a brand;
  • manufacturer statement covering a product family;
  • signed manufacturer representation naming exact models and revisions;
  • signed response plus traceable OEM, component, and service records tied to the quoted BOM.

Even the strongest supplier packet does not replace the offeror's own representation. It gives the signer a better basis.

Step 8: control substitutions

Add a purchase-order term requiring written notice before any manufacturer, OEM, hardware revision, radio, firmware branch, service provider, or country-of-origin change. Require rescreening before shipment. Low-stock substitutions are common in surveillance projects; the alternate should not inherit the original item's compliance file.

Step 9: verify at receiving and commissioning

Check labels, model and revision, serial numbers, firmware, radio identifiers, and service endpoints against the approved BOM. Photograph labels when the program permits. Quarantine unexplained variances. Update the as-built BOM after commissioning so future Part B and maintenance reviews start with reality rather than the bid list.

Supplier questions that produce usable answers

Ask the manufacturer or integrator to respond to a numbered schedule:

  • Identify the legal manufacturer and OEM for every active item.
  • Identify any item or service produced or provided by an entity named in the current covered-equipment definition, including disclosed subsidiaries and affiliates.
  • State whether any covered item is a substantial or essential component or critical technology in the offered system.
  • Describe the reasonable inquiry supporting the entity-level representation.
  • List the models, hardware revisions, firmware versions, applications, and services covered by the response.
  • Disclose dependencies that are not visible on the sales BOM.
  • Commit to notify the buyer before a covered configuration changes.
  • Name the signer, title, date, and period for which the response is valid.

Avoid asking for a single “NDAA certificate.” That phrase has no uniform evidentiary standard. A precise questionnaire creates comparable responses and makes omissions visible.

Common failure modes

Screening only the camera brand

The recorder, cellular gateway, VMS, or monitoring service may be the more important row. Review the operating system, not the storefront.

Treating TAA and Section 889 as synonyms

Trade Agreements Act origin analysis and Section 889 covered-equipment analysis answer different questions. Evidence for one does not automatically prove the other.

Treating NDAA as a product certification mark

Section 889 is implemented through acquisition prohibitions, provisions, representations, disclosures, and waivers. A badge can summarize a vendor claim but is not the rule.

Using a stale affiliate list

Ownership changes. Save the legal name, source, and date searched, and require change notification.

Skipping the entity-use question

A clean proposed BOM addresses Part A risk but does not complete Part B reasonable inquiry for the contracting entity.

Hiding uncertainty

If the OEM will not identify an embedded communications module, say so. Give the contracting authority enough detail to request clarification, accept another source, or reject the risk.

What to keep in the file

  • solicitation and amendments;
  • applicable current provisions, clauses, deviations, and agency guidance;
  • signed entity representation and reasonable-inquiry memorandum;
  • quoted, approved, and as-built BOM versions;
  • manufacturer/OEM identity evidence;
  • signed model-specific supplier responses;
  • entity and affiliate search records with dates;
  • escalation questions and contracting-officer answers;
  • waiver or disclosure documents, if applicable;
  • substitution approvals; and
  • receiving and commissioning reconciliation.

A useful retention packet explains not only the conclusion but how the buyer got there.

Frequently asked questions

Are Hikvision and Dahua cameras always prohibited?

The covered-equipment definition specifically addresses video-surveillance and telecommunications equipment from Hikvision and Dahua, including specified affiliates and subsidiaries, when used for the security and national-security purposes described in the rule. The acquisition's facts and current clause language still matter; route edge cases to the contracting authority.

Does Section 889 require a component audit?

The FAR definition of reasonable inquiry says it need not include an internal or third-party audit. That does not excuse a weak inquiry. A proposed system BOM should identify material equipment and services, and the entity representation needs a documented search designed to find relevant information in the entity's possession.

Is an “NDAA compliant” letter enough?

Not by itself. Check who signed it, the exact models and revisions it covers, the manufacturer/OEM identity, the service scope, the date, and whether it addresses Part A, Part B, or both. The offeror remains responsible for its solicitation response.

What if the OEM identity is confidential?

Ask for controlled disclosure under the acquisition's permitted process, or ask the contracting authority how to proceed. Do not translate refusal into compliance. Another product with traceable evidence may be the lower-risk choice.

Does Section 889 apply only to federal agencies?

The federal acquisition prohibitions govern executive-agency procurement and contracting. Grant, state, local, education, and prime-contractor contexts can carry related terms through awards or flow-downs. Read the specific instrument rather than assuming identical coverage.

Ask AI about Uniqcli

NDAA Section 889 screening

About the author

Uniqcli Team

Uniqcli's newsroom, buying guides and glossary are produced by our in-house team — seven procurement and technology professionals who source, screen and integrate IT and security hardware every day, working with two editors. Practitioners draft from live sourcing and integration work; editors review every piece for accuracy and plain language before it publishes.

More about the Uniqcli Team

Ready to scope your program?

Talk to a Uniqcli engineer, or send a bill of materials for a TAA-verified quote — no payment up front.